The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Light Weight Policy details

Prev Next

This URL gets the details of a light weight policy associated with a specific interface or sub interface.

Resource URL

GET /sensor/<sensor_id>/interface/<interface_id or subinterface_id>/localipspolicy

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Sensor Id Number Yes
interface_id or subinterface_id Unique interface or subinterface id Number Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
PolicyDescriptor Baseline IPS policy details Object

Details of PolicyDescriptor:

Field Name Description Data Type
PolicyName Baseline IPS policy name String
Description Policy description String
IsVisibleToChildren Is policy visible to child domain Boolean
InboundRuleSet Inbound policy rule set String
OutboundRuleSet Outbound policy rule set String
AttackCategory Attack category Object
OutboundAttackCategory Outbound attack category Object
DosPolicy DoS policy Object
ReconPolicy Recon policy Object
DosResponseSensitivityLevel DoS response sensitivity level Number
IsEditable Is policy editable Boolean
Timestamp Time stamp at which the policy was added String
VersionNum Policy version number Number
IsLightWeightPolicy Is light weight policy configured Boolean

Details of object in AttackCategory:

Field Name Description Data Type
ExpolitAttackList List of exploit attacks Array

Details of object in ExpolitAttackList:

Field Name Description Data Type
attackName Attack name String
nspId NSP id of the attack String
severity Attack severity, number between 0 & 9 Number
isSeverityCustomized Is attack severity customized Boolean
isEnabled Is attack enabled Boolean
isAlertCustomized Is alert customized Boolean
isRecommendedForSmartBlocking Is attack recommended for smart blocking Boolean
AttackResponse Attack response Object
notification Notifications configured Object
protocolList List of protocols Array
applicationsImpactedList List of applications impacted Array
attackVector List of attack vectors Array
benignTriggerProbability Attack benign trigger probability String
target Attack target, can be "Server" or "Client" String
blockingType Blocking type, can be "Attack Packet" String
subCategory Attack sub category String
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String
isAttackCustomized Is attack customized Boolean

Details of object in AttackResponse:

Field Name Description Data Type
TCPReset TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” String
isTCPResetCustomized Is TCP reset customized Boolean
isICMPSend Send ICMP host unreachable to source Boolean
isICMPSendCustomized Send ICMP host unreachable to source customized Boolean
mcafeeNACNotification NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” String
isMcafeeNACNotificationEnabled Is NAC notification enabled Boolean
isQuarantineCustomized Is quarantine customized Boolean
isRemediateEnabled Is remediate enabled Boolean
blockingOption Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” String
isBlockingOptionCustomized Is blocking option customized Boolean
isCapturedPrior Should application data be captured prior to attack Boolean
isCapturedPriorCustomized Should application data be captured prior to attack customized Boolean
action Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” String
isLogCustomized Is logging customized Boolean
flow Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” String
isFlowCustomized Customize flow type Boolean
isNbytesCustomized Is logging N bytes in each packet customized Boolean
numberOfBytesInEachPacket Number of bytes to be logged in each packet Object
loggingDuration Packet logging duration Object
TimeStamp Timestamp String

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name Description Data Type
LogEntirePacket Log entire packet Object
CaptureNBytes Capture N bytes Object

Details of object in CaptureNBytes:

Field Name Description Data Type
NumberOfBytes Number of bytes to log Number

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name Description Data Type
AttackPacketOnly Log attack packet only Object
CaptureNPackets Capture N packets Object
CaptureTimeDuration Capture for a time duration Object
RestOfFlow Capture rest of flow Object

Details of object in CaptureNPackets:

Field Name Description Data Type
npackets Log n packets number

Details of object in CaptureTimeDuration:

Field Name Description Data Type
time Capture time String
timeUnit Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" String

Details of object in notification:

Field Name Description Data Type
isEmail Is Notification configured through email Boolean
isPager Is Notification configured through pager Boolean
isScript Is Notification configured through script Boolean
isAutoAck Is Notification configured through auto ack Boolean
isSnmp Is Notification configured through SNMP Boolean
isSyslog Is Notification configured through Syslog Boolean
isEmailCustomized Is Notification through email customized Boolean
isPagerCustomized Is Notification through pager customized Boolean
isScriptCustomized Is Notification through script customized Boolean
isAutoAckCustomized Is Notification through auto ack customized Boolean
isSnmpCustomized Is Notification through SNMP customized Boolean
isSyslogCustomized Is Notification through Syslog customized Boolean

Details of object in DosPolicy:

Field Name Description Data Type
LearningAttack List of learning attacks Array
ThresholdAttack List of threshold attacks Array
TimeStamp Time stamp String

Details of object in LearningAttack:

Field Name Description Data Type
attackName Attack name String
nspId NSP id of the attack String
isSeverityCustomized Is attack severity customized Boolean
severity Attack severity, number between 0 & 9 Number
isBlockingSettingCustomized Is blocking customized Boolean
isDropPacket Drop DoS attack packets of this attack type when detected Boolean
isAlertCustomized Is alert customized Boolean
isSendAlertToManager Is alert notification to be sent to the Manager configured String
timeStamp Time stamp String
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String
notification Notification to be sent via Object
isAttackCustomized Is DoS learning attack customized Boolean

Details of object in ThresholdAttack:

Field Name Description Data Type
attackName Attack name String
nspId NSP id of the attack String
isSeverityCustomized Is attack severity customized Boolean
severity Attack severity, number between 0 & 9 Number
isThresholdValueCustomized Is threshold value customized Boolean
isThresholdDurationCustomized is threshold duration customized Boolean
ThresholdValue Threshold values Number
ThresholdDuration Threshold Interval (Seconds) Number
isAlertCustomized Is alert customized Boolean
isSendAlertToManager Is alert notification to be sent to Manager configured String
TimeStamp Time stamp String
Notification Notification to be sent Object
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String
isAttackCustomized Is DoS threshold attack customized Boolean

Details of object in ReconPolicy:

Field Name Description Data Type Mandatory
ReconAttackList List of recon attacks Array Yes
TimeStamp Time stamp String Yes
attackName Attack name String yes
nspId NSP id of the attack String Yes
isSeverityCustomized Is attack severity customized Boolean Yes
severity Severity, number between 0 & 9 Number Yes
isThresholdValueCustomized Is threshold value customized Boolean Yes
Is Threshold valuecustomized is threshold duration customized Boolean Yes
ThresholdValue Threshold values Number Yes
ThresholdDuration Threshold Interval (seconds) Number Yes
mcAfeeNACNotification Configured NAC notification that can be

"DISABLED" / "ALL_HOSTS" /

"MCAFEE_NAC_UNMANAGED_HOSTS"

String Yes
isMcAfeeNACNotificationEnable Is NAC notification enabled Boolean Yes
isQuarantineCustomized Is quarantine customized Boolean Yes
isRemediateEnabled is remediate enabled Boolean Yes
isAlertSuppressionTimerCustom Is alert suppression customized Boolean Yes
alertSuppressionTimer Alert suppression timer Number Yes
IsAlertCustomized Is alert customized Boolean Yes
isSendAlertToManager Is alert notification to be sent to Manager configured String Yes
timestamp Time stamp String Yes
direction Attack direction that can be "INBOUND" /

"OUTBOUND" / "BOTH"

String Yes
notification Notification to be sent via Object Yes
isAttackCustomized Is recon attack customized Boolean Yes

Example

Request

GET https://%3CNSM_IP%3E/sdkapi/sensor/1001/interface/105/localipspolicy

Response

{
    "PolicyDescriptor":
    {
        "PolicyName": "Local Policy - /My Company/M-2950/1A-1B clone",
        "Description": "To test the policies",
        "IsVisibleToChildren": true,
        "InboundRuleSet": "testRuleSet",
        "OutboundRuleSet": "Null",
        "AttackCategory":
       {
           "ExpolitAttackList":
           [
               {
                   "attackName": "IDENT: TinyIdentD Identification Protocol Request Handling Remote Stack Overflow",
                   "nspId": "0x42700e00",
                   "severity": 6,
                   "isSeverityCustomized": true,
                   "isEnabled": true,
                   "isAlertCustomized": false,
                   "isRecommendedForSmartBlocking": false,
                   "AttackResponse":
                   {
                       "TCPReset": "DISABLED",
                       "isTcpResetCustomized": false,
                       "isICMPSend": false,
                       "isICMPSendCustomized": false,
                       "mcAfeeNACNotification": "DISABLED",
                       "isMcAfeeNACNotificationEnabled": false,
                       "isQuarantineCustomized": false,
                       "isRemediateEnabled": false,
                       "blockingOption": "DISABLE",
                       "isBlockingOptionCustomized": false,
                       "isCapturedPrior": true,
                       "isCapturedPriorCustomized": false,
                       "action": "SEND_ALERT_ONLY",
                       "isLogCustomized": false,
                       "isFlowCustomized": false,
                       "isNbytesCustomized": false,
                       "numberOfBytesInEachPacket":
                       {
                           "LogEntirePacket":
                           {
                           }
                       }
                   },
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "protocolList":
                   [
                       "ident"
                   ],
                   "benignTriggerProbability": "3 (Medium)",
                   "blockingType": "attack-packet",
                   "subCategory": "buffer-overflow",
                   "direction": "INBOUND",
                   "isAttackCustomized": true
               }
           ]
       },
       "OutboundAttackCategory":
       {
       },
       "DosPolicy":
       {
           "LearningAttack":
           [
                {
                    "attackName": "Outbound ICMP Echo Request or Reply Volume Too High",
                    "nspId": "0x40018000",
                    "isSeverityCustomized": false,
                    "severity": 7,
                    "isBlockingSettingCustomized": false,
                    "isDropPacket": false,
                    "IsAlertCustomized": false,
                    "isSendAlertToManager": true,
                    "direction": "OUTBOUND",
                    "notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "isAttackCustomized": false
                }
            ],
            "ThresholdAttack":
            [
                {
                    "attackName": "Too Many Outbound IP Fragments",
                    "nspId": "0x40018800",
                    "isSeverityCustomized": false,
                    "severity": 6,
                    "isThresholdValueCustomized": false,
                    "isThresholdDurationCustomized": false,
                    "ThresholdValue": 1000,
                    "ThresholdDuration": 5,
                    "isAlertCustomized": false,
                    "isSendAlertToManager": false,
                    "Notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "direction": "OUTBOUND",
                    "isAttackCustomized": false
                }
            ],
            "TimeStamp": "2012-08-31 15:20:54.000"
        },
        'ReconPolicy': {
	             'TimeStamp': None,
	             'ReconAttackList': [{
		                    'IsAlertCustomized': False,
		                    'isSeverityCustomized': False,
		                    'direction': None,
		                    'severity': 5,
		                    'isThresholdDurationCustomized': False,
		                    'isSendAlertToManager': False,
		                    'isQuarantineCustomized': False,
		                    'attackName': 'BOTHeuristic: PotentialBotActivity-
MultipleResetsfromSMTPreceiver',
		                    'ThresholdDuration': 0,
		                    'alertSuppressionTimer': 0,
		                    'isAlertSuppressionTimerCustomized': False,
		                    'isAttackCustomized': False,
		                    'isMcAfeeNACNotificationEnabled': False,
		                    'isThresholdValueCustomized': False,
		                    'nspId': '0x43f00900',
		                    'mcAfeeNACNotification': 'DISABLED',
		                    'isRemediateEnabled': False,
		                    'timeStamp': None,
		                    'ThresholdValue': 0,
		                    'notification': {
			                          'isSnmp': False,
			                          'isAutoAckCustomized': False,
			                          'isPagerCustomized': False,
			                          'isSyslogCustomized': False,
			                          'isEmail': False,
			                          'isSyslog': False,
			                          'isScriptCustomized': False,
			                          'isSnmpCustomized': False,
			                          'isScript': False,
			                          'isPager': False,
			                          'isEmailCustomized': False,
			                          'isAutoAck': False
		                    }
	             }]
        },
        "DosResponseSensitivityLevel": 0,
        "IsEditable": false,
								"Timestamp": "2012-08-31 15:20:55.000",
								"VersionNum": 1, 
								"IsLightWeightPolicy": true
    }
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 404 1107 Invalid interface or sub-interface id
3 400 1301 The number of attacks does not match the number in the baseline policy
4 400 1302 Number of bytes has to be between 1 to 255
5 400 1303 Please provide the number of bytes to be logged
6 400 1304 Please provide duration of logging for flow
7 400 1305 Number of bytes has to be between 2 to 255
8 400 1306 Time has to be between 1 to 63
9 400 1307 Please provide a time
10 400 1308 Please provide a time interval
11 400 1309 Please provide the flow
12 400 1310 Invalid severity - please provide a value between 0 and 10
13 400 1311 Invalid threshold value - please enter a value between 1 and 2147483647
14 400 1312 Invalid threshold duration - please enter a value between 1 and 2147483647
15 400 1311 Alert suppression timer should be between 1 and 65535